Description |
This article describes that after renewing CA for certificate authentication, 'Error Certificate binding check failed' error appears when trying to authenticate via EAP-TLS (wireless or wired).
rlm_eap_tls: Certificate binding check failed. eap_tls: ERROR: TLS Alert write:fatal:internal error SSL routines:tls_process_client_certificate:certificate verify failed |
Scope | FortiAuthenticator using certificate authentication EAP-TLS. |
Solution |
Certificate binding refers to FortiAuthenticator being set up for reading the FortiAuthenticator certificate subject and matching it to a known CA certificate. When changing the end user's CA certificate, all user and/or machine certificates are also replaced. In order to verify the certificate chain however, FortiAuthenticator needs to have the new CA certificate installed in the GUI under Certificate Management -> TrustedCAs.
Related article: |